Out of Bounds Read Vulnerability in Systemd-Journald by Red Hat
CVE-2018-16866

4.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
11 January 2019

What is CVE-2018-16866?

An out of bounds read vulnerability exists in systemd-journald's log message parsing, particularly for messages that end with a colon ':'. This flaw can be exploited by local attackers to disclose sensitive process memory data. The vulnerability affects a wide range of systemd versions, making it critical for users to ensure they are running patched versions to protect against potential data leakage.

Affected Version(s)

systemd from v221 to v239

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

CVSS V3.0

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.